Mastering Bug Bounty Hunting: iOS & Android Edition

所在平台: Udemy

课程主页: https://www.udemy.com/course/ios-android-bug-bounty-hunting-with-burp-suite-2023/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:掌握漏洞赏金猎人:iOS与Android版 课程概述:本课程目前仍在制作中,视频内容正在持续增加。在课程完成之前,请勿进行评审。如需请求特定视频,可以联系我们。该课程旨在教授高级技巧,帮助学员发现和利用iOS与Android应用中的安全漏洞。课程内容包括对在Swift和Objective-C中开发的iOS应用安全概念的介绍,适合中级水平的学习者。 课程主题涵盖了包括iOS应用结构、逆向工程、突破客户端限制(如SSL固定和越狱检测)等内容。学员将学习如何识别多种iOS应用漏洞,包括SQL注入、薄弱的越狱检测、不安全的端到端加密和不安全的数据存储等。同时,该课程还包括创建Android实验室、攻击Android应用以及拦截应用流量以识别安全漏洞的方法。学员将接受关于FRIDA和Objection框架的介绍,从而学习SSL解固定、向运行中的应用注入JavaScript代码以及常见Android漏洞的相关知识。 在本课程中,您将学习到: - iOS和Android应用生态系统的探索 - iOS应用测试实验室的搭建 - Android应用测试实验室的搭建 - 在iOS平台上进行黑客攻击的起步 - iOS模拟器和Corellium的使用 - 越狱和SSL固定的理解 - 如何发现Android应用中的漏洞 - 使用各种Android模拟器 - FRIDA和Objection的应用 - 逆向工程移动应用以揭示漏洞 - 静态和动态分析技术的实践 - 测试iOS和Android的OWASP十大漏洞 - iOS应用的静态与动态测试 - 常见的Android和iOS应用安全问题的发现 - 针对不同类型漏洞的保护措施 - 漏洞的报告和文档记录 - 移动漏洞赏金猎人的实际案例研究 本课程将是一个动态更新的课程,如果您发现课程中有缺失的内容,我们将尽快添加。欢迎您提出主题建议和反馈意见,我们将对此进行奖励,这将有助于使课程更加有趣。

课程评论(0条)

课程详情

This Course is still being made and videos are being added, Don't Review it till the course isn't completed, You can request Videos if you want by just sending us a msg. Learn advanced techniques to find & exploit vulnerabilities in iOS and Android. Static & Dynamic Analysis for Mobile AppsIn this course, students are introduced to the security concepts related to iOS apps created in Swift and Objective-C. Intermediate-level principles are presented at the beginning of this intermediate-level course. This course covers a wide range of topics, including the structure of iOS applications, reversing iOS apps, and getting beyond client-side limitations like SSL pinning and jailbreak detection. It also demonstrates how iOS app vulnerabilities may be found and used against them. This course shows you how to spot several iOS app flaws including SQL Injection, Weak Jailbreak Detection, Insecure End-to-End Encryption, Insecure Data Storage, and others.In this course, you will learn how to set up an Android lab using Burpsuite, hack Android apps, and learn how to intercept app traffic to identify security holes. way to check an app's functionality. Additionally, we'll introduce you to the FRIDA and Objection frameworks so you can learn about SSL unpinning, injecting Javascript code into active applications, and the most well-known Android vulnerabilities.You will learn the following in this course:Exploring the iOS and Android app ecosystemsSetting up a lab for iOS app testingSetting up a lab for Android app testingHow to Start hacking on the iOS PlatformiOS Emulators and CorelliumJailbreaking and SSL PinningHow to find Vulnerabilities in Android AppsUtilizing Various Android EmulatorsFrida and ObjectionReverse engineering mobile apps to uncover vulnerabilitiesHands-on practice with static and dynamic analysis techniquesTesting for iOS and Android's OWASP Top 10 VulnerabilitiesiOS Apps Static and Dynamic TestingFinding Frequently occurring Android and iOS application security issuesProtecting against various forms of vulnerabilitiesReporting and documenting vulnerabilitiesPractical case studies in mobile bug bounty huntingThis will be a Dynamic Course, So If you find something missing here in the course, we will add it soon. You can suggest subjects and provide feedback on how to improve particular sections; we'll reward you for doing so and it'll help to make the course more interesting.

课程标签

0人关注该课程

主题相关的课程